UR E26 Goal 2 (Protect) requires malware defence + patch management + vulnerability management + system hardening. Malware defence: anti-malware (signature + heuristic + behavioral) deployed on CBS where supported; application whitelisting (allow-listing) for safety-critical CBS where anti-malware not feasible (DP + navigation + propulsion) per IEC 62443 + USB / removable media controls (block + scan + approve + log); email + web content filtering; supply chain malware checks (vendor patches + firmware + updates verified before installation). Patch management: patch identification per CBS + version + criticality; vendor + OEM patch lifecycle tracking; risk-based patch testing on shadow / staging environment before production; emergency patch procedure with vessel availability constraints; patch survey class society notification for safety-critical CBS patches; patch deferral risk acceptance documented; firmware + BIOS + microcode + container updates. Vulnerability management: CVE + vendor advisory + ICS-CERT + MUST tracking; vulnerability scanning where feasible (passive on OT); penetration testing in safe context; SBOM-based vulnerability identification. Hardening: secure baseline per CBS + IEC 62443-4-2 + STIG / CIS where applicable + disabled unused services + locked BIOS + secure boot + Trusted Platform Module (TPM) + signed boot loader. IACS UR E26 Protect + malware + patch + vuln + hardening + whitelisting + SBOM applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.